CVE-2013-1349: OS4ED Opensis

High severity, CVSS 7.5. EPSS: 22.7% chance of exploitation in the next 30 days.

Eval injection vulnerability in ajax.php in openSIS 4.5 through 5.2 allows remote attackers to execute arbitrary PHP code via the modname parameter.

Affected products

  • OS4ED Opensis: version 4.5 only; version 4.6 only; version 4.7 only; version 4.8 only; version 4.8.1 only; version 4.9 only; …

Published 2013-12-09. Last modified 2026-06-16.